CVE-2025-52222
published 2026-04-08CVE-2025-52222: D-Link DI-8003 v16.07.26A1, DI-8500 v16.07.26A1; DI-8003G v17.12.21A1, DI-8200G v17.12.20A1, DI-8200 v16.07.26A1, DI-8400 v16.07.26A1, DI-8004w v16.07.26A1…
PriorityP342high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
0.33%
25.2th percentile
D-Link DI-8003 v16.07.26A1, DI-8500 v16.07.26A1; DI-8003G v17.12.21A1, DI-8200G v17.12.20A1, DI-8200 v16.07.26A1, DI-8400 v16.07.26A1, DI-8004w v16.07.26A1, DI-8100 v16.07.26A1, and DI-8100G v17.12.20A1 were discovered to contain a buffer overflow via the rd_en, rd_auth, rd_acct, http_hadmin, http_hadminpwd, rd_key, and rd_ip parameters in the radius_asp function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| dlink | di-8003_firmware | — | — |
| dlink | di-8003g_firmware | — | — |
| dlink | di-8004w_firmware | — | — |
| dlink | di-8100_firmware | — | — |
| dlink | di-8100g_firmware | — | — |
| dlink | di-8200_firmware | — | — |
| dlink | di-8200g_firmware | — | — |
| dlink | di-8400_firmware | — | — |
| dlink | di-8500_firmware | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
D-Link DI-8003 16.07.26A1/17.12.20A1/17.12.21A1 radius_asp rd_ip buffer overflow
vuldb·2026-07-29·CVSS 7.5
CVE-2025-52222 [HIGH] D-Link DI-8003 16.07.26A1/17.12.20A1/17.12.21A1 radius_asp rd_ip buffer overflow
A vulnerability categorized as critical has been discovered in D-Link DI-8003, DI-8500, DI-8003G, DI-8200G, DI-8200, DI-8400, DI-8004w, DI-8100 and DI-8100G 16.07.26A1/17.12.20A1/17.12.21A1. The impacted element is the function radius_asp. Executing a manipulation of the argument rd_ip can lead to buffer overflow.
This vulnerability appears as CVE-2025-52222. The attack may be performed from remote. There is no available exploit.
GHSA
GHSA-gw2h-8xgr-6x93: D-Link DI-8003 v16
ghsa_unreviewed·2026-04-08
CVE-2025-52222 GHSA-gw2h-8xgr-6x93: D-Link DI-8003 v16
D-Link DI-8003 v16.07.26A1, DI-8500 v16.07.26A1; DI-8003G v17.12.21A1, DI-8200G v17.12.20A1, DI-8200 v16.07.26A1, DI-8400 v16.07.26A1, DI-8004w v16.07.26A1, DI-8100 v16.07.26A1, and DI-8100G v17.12.20A1 were discovered to contain a buffer overflow via the rd_en, rd_auth, rd_acct, http_hadmin, http_hadminpwd, rd_key, and rd_ip parameters in the radius_asp function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-04-08
Published